Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

23.388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.45%—Code-projects Simple Laundry SystemAI13/4/202617/6/2026
A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /checkupdatestatus.php. The manipulation of the argument serviceId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this issue is some unknown functionality of the file /util/BookVehicleFunction.php. Executing a manipulation of the argument BRANCH_ID can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI13/4/202617/6/2026
A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. Performing a manipulation of the argument BRANCH_ID results in sql injection. The attack is possible to be carried out…
AnalizadaAlta (7.1)0.13%—Libexif Project Libexif12/4/202617/6/2026
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
AnalizadaAlta (7.1)0.13%—Libexif Project Libexif12/4/202617/6/2026
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
AnalizadaAlta (7.1)0.28%—MYT Project MYT12/4/202617/6/2026
MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query…
AplazadaAlta (8.6)0.19%—R Project RAI12/4/202615/7/2026
R 3.4.4 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by injecting malicious input into the GUI Preferences language field. Attackers can craft a payload with a 292-byte offset and JMP ESP instruction to execute commands like calc.exe when the payload is pasted into the…
ModificadaBaja (3.3)0.14%—Systemd Project Systemd10/4/202617/6/2026
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
AnalizadaMedia (5.5)0.29%—Systemd Project Systemd10/4/202617/6/2026
In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.
AnalizadaMedia (6.4)0.09%—Systemd Project Systemd10/4/202617/6/2026
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
AnalizadaMedia (6.4)0.21%—Systemd Project Systemd10/4/202617/6/2026
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
AnalizadaAlta (7.3)0.12%—Systemd Project Systemd10/4/202617/6/2026
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
AnalizadaMedia (5.5)0.12%—Systemd Project Systemd10/4/202617/6/2026
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.
AplazadaAlta (8.7)0.31%—Atom 3X ProjectorAI10/4/202617/6/2026
This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI10/4/202617/6/2026
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI10/4/202617/6/2026
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.41%—Code-projects Vehicle Showroom Management SystemAI10/4/202617/6/2026
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been made public and…
AplazadaBaja (2.1)0.45%—Code-projects Vehicle Showroom Management SystemAI10/4/202617/6/2026
A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation of the argument BRANCH_ID leads to cross site scripting. Remote exploitation of the attack is possible. The…
AplazadaBaja (2.1)0.45%—Code-projects Vehicle Showroom Management SystemAI10/4/202617/6/2026
A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCH_ID can lead to cross site scripting. The attack may be launched remotely. The exploit has been published…
AplazadaBaja (2.1)0.45%—Code-projects Simple Laundry SystemAI10/4/202617/6/2026
A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument serviceId results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AplazadaBaja (2.1)0.32%—Code-projects Patient Record Management SystemAI10/4/202617/6/2026
A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AplazadaBaja (2.1)0.32%—Code-projects Patient Record Management SystemAI10/4/202617/6/2026
A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaBaja (1.9)0.35%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and…